Fooder

S9033

Malware.View on attack.mitre.org

About this malware

Fooder is a custom 64-bit C/C++ loader used by MuddyWater that can decrypt and reflectively load embedded payloads such as a go-socks5 proxy utility, the open-source HackBrowserData infostealer, or the MuddyViper backdoor. Fooder has frequently masqueraded as an entertainment executable, such as the Snake game (e.g., `Snake_Game.exe`).

Techniques used7

Procedure examples7

TechniqueProcedure example
T1027
Obfuscated Files or Information

Fooder has stored its embedded payload in encrypted form within the binary, using a hardcoded key modified at runtime to produce the AES decryption key.

T1036.005
Match Legitimate Resource Name or Location

Fooder has frequently masqueraded as the Snake game, using strings such as “Welcome to snake Game” and mutexes such as “SNAKE_G.”

T1106
Native API

Fooder has used the WinCrypt API for payload decryption, `DuplicateTokenEx` to duplicate the token of a specified process, and `CreateProcessAsUserA` for payload execution.

T1134.001
Token Impersonation/Theft

Fooder has used the `DuplicateTokenEx` API to duplicate the token of a specified process, and `CreateProcessAsUserA` to execute its payload.

T1140
Deobfuscate/Decode Files or Information

Fooder has decrypted payloads using the WinCrypt API and the AES key.

T1620
Reflective Code Loading

Fooder has reflectively loaded a payload into memory.

T1678
Delay Execution

Fooder has used a custom delay function (`delayExecution(integer)`) and Sleep API calls (`Sleep(integer)`) to slow code execution.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET_MuddyWater_Dec2025 Open source
    ESET Research. (2025, December 2). MuddyWater: Snakes by the riverbank. Retrieved February 17, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.